[Bug 1087501] Re: Unable to boot unsigned kernel, boot freezes in shim call

Steve Langasek steve.langasek at canonical.com
Wed Jul 10 00:40:59 UTC 2013


Stéphane has reported that with the build of shim 0.4, the problem is
worse: both signed and unsigned kernels now fail.  This seems to fit if
the bug is in shim's own image verification - between the raring version
of shim and shim 0.4, upstream has changed to use its internal SB
verification code exclusively, instead of trying the firmware's
verification routine first and falling back to its implementation only
on failure.

Stéphane, can you please give the attached shimx64.efi a go, and post
the console output so we can see where it hangs?  Binary signed with the
same key as the other one for bug #1187233.  Will need to iterate this a
few times to get to the bottom, I expect.

** Attachment added: "shimx64.efi"
   https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1087501/+attachment/3731196/+files/shimx64.efi

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to shim in Ubuntu.
https://bugs.launchpad.net/bugs/1087501

Title:
  Unable to boot unsigned kernel, boot freezes in shim call

Status in “shim” package in Ubuntu:
  Incomplete

Bug description:
  On a Lenovo x230 with secureboot enabled, I can only boot signed
  kernel.

  Initially this was thought to be a grub2 issue but after investigation
  (added debug code in grub and running with debug=all), it was
  determined that the last thing grub does before the freeze is call a
  shim hook.

  The current workaround is to either disable secureboot or use a signed
  kernel.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1087501/+subscriptions




More information about the foundations-bugs mailing list